Skip to content
  • Features
  • Safety
  • Help
  • Legal
Get the app
  • Features
  • Safety
  • Questions
  • Help and contact
  • Delete your account
  • Legal
Get the app
Legal

Privacy Policy

What information SocialZoom collects, how we use and share it, how long we keep it, and the choices and rights you have.

Last updated 17 September 2026

On this page
  1. The short version
  2. 1. Who we are and how to reach us
  3. 2. Information you give us
  4. 3. Information we collect automatically
  5. 4. How we use your information
  6. 5. What other people can see
  7. 5a. "Active now" and when you were last active
  8. 6. Your messages
  9. 6a. Inviting a friend, and the phone number check
  10. 6b. GIFs
  11. 6c. Voice calls
  12. 6d. Group chats
  13. 7. How we share information
  14. 8. Where your information is stored
  15. 9. How long we keep information
  16. 10. Your choices in the app
  17. 11. Your rights
  18. 12. Children
  19. 13. Security
  20. 14. Cookies on our website
  21. 15. Changes to this policy
  22. 16. Contact us and Grievance Officer

SocialZoom is a social platform for digital marketing. Small businesses, creators, marketers and anyone sharing their work use it to post about what they do, grow an audience and talk to customers.

This policy explains how we handle personal information when you use the SocialZoom app for iPhone and Android, our website socialzoom.co, and the marketing services you buy directly from us.

SocialZoom is run by Suraj Kumar Rajak (trading as Social Zoom) ("SocialZoom", "we", "us"), a business based in India. We decide how your information is used, so we are responsible for it. (Under Europe’s GDPR we are the "controller". Under India’s Digital Personal Data Protection Act, 2023 we are the "Data Fiduciary".)

The short version

  • We collect what you give us (your account details, profile, posts and messages) and some technical information we need to run SocialZoom and keep it safe.
  • We never sell your personal data.
  • There are no advertising trackers and no analytics services in the app, and our website uses no analytics or advertising cookies. Some Google software inside the app (Firebase, and ML Kit for the QR code scanner on Android) sends Google technical information about how that software is working; see section 3. If any of this changes, we’ll update this policy first.
  • If we ever add promoted or sponsored posts, they will be clearly labelled.
  • New accounts are private. Only the people you approve can see your posts. You can make your account public in Settings.
  • Your email address, date of birth, country and phone number are never shown on your profile.
  • Your messages can only be seen by the people in the chat. They are not end-to-end encrypted.
  • Voice calls are encrypted end to end. We cannot hear them, and we never store them.
  • People you chat with, and people allowed to see your posts, can see when you were last active. You can turn this off in Settings (section 5a).
  • SocialZoom does not ask for your device’s location, and does not use it. When you add a place to a post, it is a name you typed.
  • We send you service messages about your account. We’ll only send you marketing emails if you agree, and you can always unsubscribe.
  • You can download your data or delete your account at any time in Settings, or on this website.

1. Who we are and how to reach us

  • Company: Suraj Kumar Rajak (trading as Social Zoom), 38 Bhagwan Nagar, Ashram, New Delhi 110014, India
  • Privacy questions and requests: privacy@socialzoom.co
  • Grievance Officer (India): Suraj Kumar Rajak, suraj@socialzoom.co. See section 16.

2. Information you give us

When you sign up

  • Email address and password. You sign in with these. Our sign-in service stores your password only as a secure hash, a scrambled form that can’t be turned back into your password. We never see or store your actual password.
  • Full name, date of birth and country. We ask for these after your email and password.
    • We use your date of birth to check that you are at least 13. You can’t create an account if you are younger.
    • We keep your country with your account details, so we know which country’s laws apply to you.
    • A phone number — only if you use a friend’s invite code. Signing up does not ask for a phone number at all. If you enter an invite (referral) code, we ask for your number and send you a text with a 6-digit code to check that it is yours. You can skip that: your account works exactly the same, and the invite simply doesn’t count until the number is checked. See section 6a for what we do with it.
    • Username. You choose it as the last step of sign-up.

We email you a one-time code to confirm your email address, and we may ask for a code sent to your email when you log in.

Until you choose a username, your account is not visible to anyone. If you start signing up but don’t finish, we automatically delete the unfinished account after 24 hours of inactivity.

Your profile

Your profile shows your name and username, and, if you add them, a profile photo, a bio and a website link. It also shows a verified tick and your Pro status if you have SocialZoom Pro, including the date your Pro subscription ends.

The app doesn’t ask for business details, such as a company registration or tax number. If you use SocialZoom for your business or brand, what you put in your profile and posts is up to you.

What you post and share

  • Posts: photos and videos, with captions, hashtags and @mentions. You can hide the like count on a post, turn off comments, and pin up to 3 posts to your profile.
  • Stories: photos and videos that others can see for 24 hours. After that they stay in your story archive, which only you can see, unless you add them to a highlight on your profile. You can see who viewed each of your stories.
  • Comments, likes, follows and saved posts.
  • People you tag in a photo. When you tag someone, we store who you tagged, which photo, and the point on the photo you placed the tag on. The post then appears in that person’s Tagged tab. Anyone you tag can remove their own tag.
  • A place on a post. This is a name you type, such as a shop, a venue or a city. We do not use your device’s location to work it out, and the app never asks for location permission. There is no map, no place search and no address lookup behind this field: whatever you type is what we store.
  • Direct messages and group chats: text, photos and videos, voice notes, stickers, GIFs, emoji, reactions and replies (see sections 6 and 6d). If you create a group, its name and photo.
  • Voice calls: a record of each call you make or receive, but never the sound (see section 6c).
  • Reports you make about posts or accounts: what you reported, the reason, and any details you add.
  • Your safety settings: the accounts you block and your hidden words.
  • A referral code, if you enter one when you sign up, or share your own. See section 6a.

When you buy SocialZoom Pro

Payments are handled by the Apple App Store, Google Play or, on our website, Razorpay. Your card details go to them, never to us. We receive what we need to give you Pro: confirmation of the purchase, where you bought it, and whether your subscription is active, renewed, cancelled or ended.

When you buy a marketing service from us

This applies only if you buy one of our marketing services directly from us, such as social media management, content creation, email marketing or a monthly promotional plan. To deliver it, we use the information you give us: your name and contact details, your business or brand name, and the content, materials and instructions you send us. If your plan includes managing one of your social media accounts, we use the access you give us only for that work. Payments on our website are processed by Razorpay, and we never see your card details.

When you contact us

If you email us, we keep your message, your email address and anything else you choose to tell us, so we can help you.

3. Information we collect automatically

  • Server logs. When your app or browser talks to our servers, we record your IP address and details of the request, such as the time, what was requested, and the app or browser that made it. We use these logs for security, to prevent abuse and to fix problems. An IP address can show your approximate location, such as your city or country.
  • Sign-in sessions. We keep a record of each device you are logged in on: the type of device or browser, when it logged in and when it was last active. You can see this list in Settings under Where you’re logged in, and log out of other devices there.
  • Security alerts. When someone signs in to your account, we use the IP address and the type of app or browser of that sign-in to email you an alert, so you can tell if it wasn’t you. When your email address or password changes, the alert shows the IP address of the device most recently active on your account. We don’t send these alerts for your first sign-in when you create your account.
  • When you were last active. The minute you last used the app, so we can show "Active now" or "Active 12m ago" to the people allowed to see it. We keep one time for each account and overwrite it, so there is no history of when or how long you use SocialZoom. See section 5a.
  • Push notification token. A code from Apple or Google that lets us send notifications to your device. We keep one record for each device you use SocialZoom on, holding the token, whether the device is an Android phone or an iPhone, the version of the app on it, and when we last saw it. We store nothing else about the device: no model, no serial number, no advertising identifier. If we haven’t seen a device for 180 days, we delete its record.
  • Which notifications you want. Your choices from the notification switches in Settings: likes, comments, follows, mentions, tags, messages and announcements, along with any quiet hours you set.
  • Your phone’s time zone. The time zone your phone is set to, such as "America/Los_Angeles", so that the times in emails about your account, such as a new sign-in alert, are in your own time. It comes from your phone’s settings, not from your phone’s location, and we update it when your phone’s time zone changes. It is deleted with your account.
  • App version. So we know which version of the app you use.
  • Login protection. To stop people guessing passwords, we count wrong password attempts for each username and each network address. We store these counts only as one-way digests (they can’t be turned back into the username or address), and we keep them only for a short time.
  • Firebase. The app includes Google’s Firebase software: Firebase Cloud Messaging delivers push notifications, and Firebase Remote Config delivers app settings. It creates an identifier for your installation of the app and sends basic technical details about the app and your device to Google.
  • Google ML Kit (the QR code scanner on Android). On Android, the scanner that reads a profile QR code uses Google’s ML Kit. The scanning happens on your phone: the camera picture is not sent to Google or to us. Like every app that uses ML Kit, it may contact Google’s servers from time to time for things like bug fixes and updated models, and it sends Google information about how ML Kit is performing and being used, such as your device model, operating system and app version, and error codes. Google uses this to measure ML Kit’s performance, fix and improve it, and detect misuse, under Google’s own privacy policy. On iPhone, the scanner uses Apple’s own Vision software on the phone instead of ML Kit.

Device permissions

The app asks for permission before it uses:

  • Camera: so you can take photos, film videos and scan a profile QR code in the app.
  • Microphone: so you can talk on a voice call, record a voice note in a chat, and so a video you film has sound.
  • Photos and videos on your device: so you can choose what to share, and save media to your device.
  • Notifications: so we can send you push notifications, including when someone calls you, if you allow them. We ask when the app starts, once you’re signed in. If you say no, we don’t ask again, and the app works normally without them.

You can change these permissions at any time in your device settings.

SocialZoom never asks for your location, and never asks for your contacts. There is no location permission in the app on either Android or iPhone, and no part of the app can read where you are. This is deliberate, and we test for it: a check that runs every time the app is built lists the exact permissions the app is allowed to ask for, and it fails if a location or contacts permission is ever added. If that ever changes, we will update this policy before the new version reaches you.

4. How we use your information

We use your information to:

  • create and run your account, and let you sign in;
  • show your profile and posts to other people, and deliver your messages;
  • connect your voice calls, and run your group chats;
  • show when you were last active, unless you turn it off;
  • send you notifications about activity, such as new followers, likes, comments, messages and calls;
  • provide SocialZoom Pro, and any marketing service you buy from us;
  • keep SocialZoom safe: review reports, enforce our Community Guidelines, stop spam and abuse, and protect accounts from being broken into;
  • check that a referral is genuine, and stop one person making many accounts to collect rewards (section 6a);
  • find and fix problems, and keep the service running reliably;
  • send you service messages about your account, security, purchases and changes to our terms;
  • follow the law, including responding to valid legal requests and reporting child sexual abuse material to the authorities.

Emails. Today we only send service messages. We’ll only send you marketing emails, such as news and offers, if you have agreed to receive them, and every marketing email will include a way to unsubscribe.

Promoted posts. We never sell your personal data. If we ever add promoted or sponsored posts, they will be clearly labelled, and we’ll update this policy before we use any of your information to decide which ones you see.

Some of our processing is automatic. For example, the hidden words filter hides comments and messages that contain offensive words, and our login protection pauses sign-in attempts after too many wrong passwords. We don’t make decisions about you based only on automated processing that have legal or similarly significant effects on you.

5. What other people can see

New accounts are private. When you create an account, only people you approve as followers can see your posts, stories and the people you follow. Someone who wants to follow you sends a request, and you accept or decline it. You can make your account public at any time in Settings, and switch it back.

  • Always visible to anyone on SocialZoom, whether your account is private or public: your name, username, profile photo, bio, website link, verified tick and Pro status (including when your Pro ends), and your follower and following counts. This is what someone sees when they find you and decide whether to follow you.
  • Visible to your approved followers, if your account is private - to anyone, if it is public: your posts, your stories for 24 hours, your comments and likes, and who follows you and who you follow.
  • Tags: if you tag someone in a photo, they can see it and the post appears in their Tagged tab. If someone tags you, you can remove the tag.
  • Story viewers: when you view someone’s story, they can see that you viewed it.
  • Group chats: everyone in a group can see its name, its photo, who is in it and the messages in it (section 6d).
  • When you were last active: see section 5a.
  • Only you: your saved posts, your story archive, the accounts you’ve blocked, your hidden words, your referral code and who used it, and the devices you’re logged in on.
  • Never shown on your profile: your email address, date of birth, country and phone number.

One limit on private accounts you should know about. Making your account private stops people seeing your posts inside SocialZoom. It does not make the photo files themselves secret: if someone already has the direct web address of a photo you uploaded - because they could see it before you went private, or because it was passed on to them - that address keeps working. Treat anything you have already posted as something that may have been copied. We are changing how this works; until we have, this is the honest description. The same is true of a group chat’s photo.

Since 14 September 2026, most public photos (photos in posts and stories, cover photos and group photos) reach your phone through Cloudflare’s network, which keeps copies for up to a day so they load faster. So after a photo is deleted, someone who already has its exact web address may still be able to open it for up to a day. Photos, videos and voice notes sent in a chat never go through this.

Anything you share can be copied, screenshotted or shared again by the people who see it. Please think about that before you post, especially when you share details about your business or your customers.

5a. "Active now" and when you were last active

When you use SocialZoom, we note the minute you were last active, so the app can show "Active now", or something like "Active 12m ago", under your name in a chat and on your profile. We keep just that one time for each account and overwrite it, so there is no record of when, or for how long, you used the app before that.

Who can see it. Activity status is on unless you turn it off. Someone can see yours only if they are signed in, both of you have activity status turned on, and they are:

  • an approved follower of yours, or anyone on SocialZoom if your account is public; or
  • someone you have a one-to-one chat with that both of you have accepted.

It is never shown to someone you have blocked or who has blocked you. Being in the same group chat doesn’t count. Nothing is shown once you haven’t been active for 7 days, and we clear the stored time after that.

Turning it off. In Settings, under Privacy, turn off Activity status. Nobody will then see when you were last active, in a chat or on your profile, and the time we had stored is erased, not just hidden. It works both ways: while yours is off, you won’t see when anyone else was active either. You can turn it back on whenever you like.

6. Your messages

  • Direct messages can only be seen by the people in the conversation. Photos, videos and voice notes sent in a chat can only be opened by the people in that chat, through links that expire after a short time.
  • What a message can contain: text, photos, videos, voice notes, stickers, GIFs, emoji, reactions and replies. A voice note is recorded on your phone when you hold the microphone button, and is only uploaded when you send it. If you cancel, the recording is deleted from your phone and never reaches us.
  • Link previews. When you type a web link in a chat, your phone opens that web page in the background to make a preview of it. That website can see your device’s internet address, as it would if you visited it.
  • Stickers are artwork that comes with the app. Choosing one tells us which sticker you sent, the same way text tells us what you typed. Nothing is sent to anyone outside SocialZoom.
  • People you don’t follow can send you a message request. You decide whether to accept it.
  • Messages are not end-to-end encrypted. They are encrypted while they travel between your device and our servers, and our servers check that only the people in a chat can read it. But they are stored on our servers in a form our systems can read. We don’t read your messages as a matter of routine. We may look at them when we need to, for example to investigate a report, to protect someone’s safety, or when the law requires it.
  • Unsend: removes a message from the chat for everyone. If someone replied to it before you unsent it, a copy of the quoted text can stay with their reply on our servers, but the app never shows it.
  • Reporting a message. If you report a message somebody sent you, that message is copied and shown to our moderators: the text, or the photo, video or voice note. It has to be: we have no way to look into a conversation, and we are not building one, so a report that didn’t carry the message would be a report nobody could act on. Only the one message you reported is copied, only because you chose to report it, and the copy is kept with the report and deleted when the report is. Only someone in the conversation can report a message in it. The same applies to a story you report.
  • Vanish mode: messages disappear once they have been seen and the chat is closed. If our servers still hold a vanish message after it has been seen, we remove it 24 hours after it was seen. The exception is a message you report: the copy made for the report stays with the report, because a message that deletes itself is exactly the kind somebody needs to be able to report. Vanish mode can’t stop someone from taking a screenshot or a photo of their screen.
  • Delete chat: removes the chat from your inbox only. The other person keeps their copy. If they send you a new message, the chat comes back and shows only the new messages.

6a. Inviting a friend, and the phone number check

Every account gets a referral code you can share. If someone enters your code when they sign up, we record that you referred them, and the two of you are the only people who can see that record.

Why we ask for a phone number here. A referral programme is worth money, so people try to farm it by making many accounts. A number nobody checks stops none of that, so if you enter a code we ask for your number and check it with a text message. The text is sent for us by Google Firebase, part of Google Cloud, which receives your number to send it and to stop abuse of its own service. As soon as the check is done we delete the temporary Firebase sign-in it made. Your number is then kept with your account details, and it is never shown to anyone.

  • One number per account, and one account per number: a number already checked on another account can’t be used for a second invite.
  • Entering a code, and checking a number, are both optional. Skip either and nothing is asked for and nothing is kept.
  • You can ask us to delete the number at any time (privacy@socialzoom.co); the invite then stops counting.

What a person reviewing an invite sees. When a code is used we also work out a digest of the phone number on each of the two accounts and store the two digests against the invite. A digest is a scrambled version of a number: we do not store your phone number in that record, and the digest is not shown to anybody. What a member of our team reviewing an invite sees is whether the number was checked, a yes-or-no answer to "did these two accounts give the same number?", and how many invites that number appears on. They never see the number.

The digest is made with a secret key that we keep separately from the digests themselves. That matters, and here is why we bother to explain it. An Indian mobile number has only about four billion possible forms, so a plain digest of one can be turned back into the number by anybody willing to try all four billion - which is a few hours of ordinary computing. Adding a key we hold takes that off the table: without the key, there is nothing to try. It is not a promise that nothing can ever go wrong, but it is meaningfully stronger than "scrambled", and we would rather say which one we do.

  • We use the digests only to decide whether a referral is genuine. We use them for nothing else, and we never use them to contact you.
  • The phone number itself is kept with your account details, as section 2 describes. We text it once, to check it, and never again.
  • Entering a code is optional. If you skip it, no digest is made.
  • We delete the digests 90 days after the referral is decided, or 90 days after the code was used if nobody ever decided it.

One record outlives your account, and we want you to know about it. When a code is used, we also keep a single separate record meaning "this number has already claimed a referral". It holds the keyed digest and the date, and nothing else - no name, no account, no way to point back at you. It is there so that deleting an account and signing up again on the same number cannot be used to claim a second reward, which is the most obvious way to farm the programme.

This is the only thing we keep about you after you delete your account, other than the things named elsewhere in section 9. It is deleted 90 days after the referral was claimed, whether or not the account still exists. If the referral is rejected by our team, the record is deleted straight away, so a decision that went your way does not cost you anything.

6b. GIFs

The GIF tab in a chat is provided by Klipy, a third-party GIF service. When you open the tab or search in it, your device asks Klipy for GIFs directly. Klipy receives what you type in the GIF search box, which GIF you pick when you send one, and your device’s internet address. It does not receive your name, your username, your account, or any identifier for you or your phone. We always ask Klipy to filter out adult results.

The GIF pictures themselves stay on Klipy’s servers. When a chat shows a GIF, including one somebody sent you, your phone loads it from Klipy, so Klipy can see your device’s internet address then too, but nothing that says who you are.

If you never open the GIF tab and nobody sends you a GIF, nothing reaches Klipy. A GIF you send is stored as part of that chat, like any other message.

Klipy handles what it receives under its own privacy policy, which we don’t control.

6c. Voice calls

You can make a one-to-one voice call to someone you already have an accepted chat with. A stranger cannot call you: reaching a chat with you means getting past your message request first. There are no calls in group chats.

We cannot hear your calls. Calls use WebRTC, the standard technology behind most calling apps. The sound is encrypted on your phone and decrypted on the other person’s, and it is never recorded or stored. Nobody at SocialZoom can listen to a call, and neither can the servers that help connect it. Our servers pass along the short setup messages the two phones use to find each other, and don’t store them.

How the call connects, and what that means for your internet address. Where your two phones can reach each other directly, the sound travels straight between them. That is the fastest and clearest route, and it is what happens most of the time. It also means each of you can see the other’s internet address once the call is answered, which is true of every calling app that connects people directly.

Where a direct connection isn’t possible (some mobile networks and office networks don’t allow it), the sound goes through a relay server we run in France. The relay passes the encrypted sound along without being able to open it. It can see the internet addresses of both phones, when the call happened and how much data passed through.

What we keep about a call: who called whom, when it started, whether it was answered, declined or missed, how long it lasted, and which device placed it and which answered it (a random code the app makes up, not a hardware ID). We use this to show the call in your chat, such as "Voice call · 3:12" or "Missed voice call", and so that only one of your phones answers. To stop somebody ringing you over and over, we also count the calls each account places, stored only as scrambled digests and deleted after a day. We do not keep the sound, because we never have it.

If someone calls while SocialZoom isn’t open, we send you a push notification about the call, in the same way as for messages.

Blocking someone ends any call with them and stops them calling you again.

6d. Group chats

A group chat has between 3 and 32 people. The person who creates it is its admin.

  • Who can add you. Only the admin can add people, and only people who have already chosen them: someone who follows the admin, or who already has a chat with them that both of them accepted. Someone you have blocked, or who has blocked you, can never add you. If you don’t follow the person who added you, the group arrives in your message requests.
  • What members see. Everyone in a group can see its name, its photo, who is in it, and the messages in it, including messages sent before they joined. Only the admin can change the name and photo. The group photo is stored like a profile photo, so anyone who has its exact web address can open it (see section 5).
  • Your messages. Group messages work like direct messages (section 6): they are not end-to-end encrypted, and vanish mode isn’t available in groups.
  • Blocking inside a group. Blocking someone doesn’t remove them, or their messages, from a group you are both in. The app hides their messages from you behind a tap and offers you the choice to leave.
  • Leaving. You can leave a group at any time. The group and its messages then disappear from your phone, the others see a line saying you left, and the messages you sent stay in the group for the people still in it. Once you have left, nobody can add you back to that group.
  • Being removed. The admin can remove people. The group sees a line saying who was removed. The group disappears from the removed person’s phone in the same way, and their messages stay. Only the admin who removed them can add them back.
  • If the admin leaves, the group carries on without an admin: everyone can still talk and leave, but nobody can add, remove or rename.

To make these rules work, we keep a record of when someone left or was removed from a group, and by whom. When you delete your account, the messages you sent in groups are deleted along with everything else (section 9).

7. How we share information

We never sell your personal data. We share it only in these cases.

Service providers who help us run SocialZoom

They may use your information only to provide their service to us.

  • Contabo: our servers, including the relay that helps connect voice calls, located in France (European Union).
  • Cloudflare: storage for photos, videos and voice notes (Cloudflare R2); delivering public photos from its network at media.socialzoom.co (section 5); our domain name system (DNS); and protection of our network from attacks.
  • ZeptoMail (by Zoho): sends emails about your account, such as sign-in codes and security alerts.
  • Google Firebase: delivers push notifications (Firebase Cloud Messaging) and app settings (Firebase Remote Config).
  • Apple Push Notification service: delivers push notifications to iPhones.

Klipy

If you use the GIF tab in a chat, your device contacts Klipy directly with what you type there, the GIF you pick and your internet address, and a GIF shown in a chat is loaded from Klipy. Klipy is not acting on our behalf in the way the providers above are, and it handles that information under its own privacy policy. See section 6b.

Google ML Kit

On Android, the QR code scanner’s ML Kit software sends Google information about how ML Kit is performing and being used, which Google handles under its own privacy policy. The camera picture stays on your phone. See section 3.

Payment providers

If you buy Pro or a marketing plan, the Apple App Store, Google Play or Razorpay handle your payment under their own terms and privacy policies.

Partners who help deliver a service you bought

If a marketing service you buy from us involves a partner, we share only what that partner needs to deliver the service, and only for that purpose.

For legal and safety reasons

We may share information when we believe in good faith that the law requires it, for example to comply with a court order or a valid request from law enforcement. We may also share it to protect the safety of any person, to prevent fraud or abuse, or to defend our legal rights. We report child sexual abuse material to the authorities, including India’s National Cyber Crime Reporting Portal and, where applicable, the US National Center for Missing & Exploited Children (NCMEC). See our Child Safety Standards.

If our business changes

If SocialZoom is involved in a merger, acquisition or sale of assets, your information may be transferred as part of that deal. We’ll tell you before your information becomes subject to a different privacy policy.

With your permission

We share information in other ways only if you ask us to or agree to it.

8. Where your information is stored

Our servers, including the voice call relay, are in France, in the European Union. Public photos are delivered from Cloudflare’s servers around the world, usually one near you. Some of our service providers, including Cloudflare and Google, may process information in other countries, including the United States. We are based in India, and our team may access information from India.

When personal information from the European Economic Area or the UK goes to a country that doesn’t have an "adequacy decision", we use safeguards recognised by law, such as the European Commission’s standard contractual clauses.

9. How long we keep information

InformationHow long we keep it
Your account and profileUntil you delete your account
Posts, comments, likes, follows and saved postsUntil you delete them, or delete your account
Photo tags and the place on a postWith the post. Removing a tag hides it straight away
StoriesShown for 24 hours, then kept in your archive until you delete them or your account
Messages you send, including voice notes, stickers and GIFsUntil you unsend them or delete your account. If you leave a group, the messages you sent stay in it. Vanish messages: see section 6
Call records: who called whom, when, how long, and whether it was answered or missedUntil you or the other person deletes their account. We never hold the sound
Call rate-limit counts (scrambled digests)About a day
A group chat’s name, photo and member listWhile the group exists. A replaced group photo, or the photo of a group everyone has left, is queued for removal from our storage
The record that someone left or was removed from a groupUntil that person deletes their account
When you were last activeOne time, overwritten each time you use the app. Cleared after 7 days, or straight away when you turn activity status off
Copies of public photos in Cloudflare’s cacheUp to a day
Unfinished sign-upsDeleted after 24 hours of inactivity
Details for a marketing service you boughtWhile we provide the service, then only as long as we need them for our records, to resolve disputes or to meet legal requirements
Your agreement to receive marketing emailsUntil you unsubscribe
Server logs180 days
Login protection countsA short time only
Sign-in sessionsUntil you log out, log out of other devices, or the session expires
Security alerts and account emails we send you (a new sign-in, a changed email address or password, Pro or the verified tick)The IP address and your email address are removed as soon as the email is sent (or can no longer be sent). The record that it was sent is deleted after 30 days
Push notification tokenUntil you delete your account, log out on that device, or 180 days after we last saw the device
The text of a notification we sent youRemoved as soon as the notification is delivered (or can no longer be)
The record that a notification was sent7 days (90 days for announcements and warnings from our team)
Phone number digests kept against a referral (section 6a)90 days after the referral is decided, or 90 days after the code was used if it was never decided
The record that a number has claimed a referral (section 6a)90 days from the claim - including if you delete your account in the meantime. Deleted immediately if the referral is rejected
ReportsKept after an account is deleted, so they can still be reviewed, but no longer linked to that account
The copy of a message or story you reported (section 6)With the report, and deleted when the report is
Records of purchasesAs long as tax and accounting laws require
BackupsUp to 30 days

The text of notifications. When we send you a notification, we keep its title and one line of text (for a message, a line of that message) only until it has been handed to Apple or Google for delivery, or can no longer be delivered. Then we remove the text. The record that it was sent, without the text, is deleted after 7 days, or 90 days for announcements and warnings from our team.

When you delete your account, we delete it straight away, including the messages you sent (in group chats too), your call records, your place in any group and the time you were last active. The photos and videos you uploaded are removed from our storage within 30 days. The one exception is the referral record described in section 6a, which holds no name or account and goes after 90 days. Our account deletion page explains exactly what is deleted and what is kept.

If we close your account for breaking our rules, rather than you deleting it yourself, we hold it for 30 days before erasing it. During that time your profile and posts are hidden from everyone. This gives us time to deal with an appeal, and to answer the authorities if the closure involved illegal content.

We may keep specific information for longer if the law requires it, or if we need it for a legal claim or an investigation, for example into a report of child sexual abuse material.

10. Your choices in the app

  • Edit your profile, and delete your posts, stories and comments.
  • Keep your account private, or make it public. New accounts start private. In Settings you can switch it either way, and approve or decline each follow request.
  • Hide like counts, turn off comments, and pin posts.
  • Remove a tag someone put on you, and decide what appears in your Tagged tab.
  • Unsend messages, use vanish mode, and delete chats from your inbox.
  • Leave any group chat at any time (section 6d).
  • Turn off activity status in Settings, under Privacy, so nobody sees when you were last active (section 5a).
  • Block accounts, report posts and accounts, and manage hidden words (on by default). Blocking someone also ends any call with them.
  • See where you’re logged in, and log out of other devices.
  • Choose which notifications you get - likes, comments, follows, mentions, tags, messages and announcements - in Settings, and turn them off altogether, including call notifications, in your device settings.
  • Unsubscribe from any marketing email we send, using the link in the email.
  • Download your data: in Settings, get a file with a copy of your SocialZoom information.
  • Delete your account: in Settings, or on our account deletion page.

11. Your rights

Wherever you live, you can ask us to:

  • tell you what personal information we hold about you, and give you a copy;
  • correct or update it;
  • delete it.

You can do most of this yourself in the app. For anything else, including a copy of information that isn’t in your data download, email privacy@socialzoom.co. We may need to confirm your identity first. We’ll reply within one month. If a request is complex, we may need longer, and we’ll tell you why.

If you live in the European Economic Area or the UK

Under the GDPR (and the UK GDPR) you also have the right to:

  • restrict how we use your information;
  • get your information in a portable format;
  • object to us using your information based on our legitimate interests;
  • withdraw your consent at any time, where we rely on consent (this doesn’t affect what we did before);
  • complain to a data protection authority. You can contact the authority in the EU country where you live or work, or where you think the problem happened (the European Data Protection Board’s website lists them), or the Information Commissioner’s Office if you are in the UK. We’d appreciate the chance to sort out your concern first, so please contact us.

Our legal bases for using your information:

Why we use itLegal basis
To run your account and provide SocialZoom, including messages, group chats, voice calls, activity status, Pro and any marketing service you buyIt’s necessary to provide the service you signed up for or bought (contract)
To check your ageTo meet our legal obligations, and our legitimate interest in keeping children under 13 off SocialZoom
For security, preventing abuse, reviewing reports and enforcing our rulesOur legitimate interest in keeping SocialZoom and the people on it safe
To check a referral is genuine, using the phone number digests in section 6aOur legitimate interest in preventing fraud against our own referral programme
To send push notificationsYour consent, which you give and can take back in your device settings
To send marketing emailsYour consent, which you can take back at any time by unsubscribing
To follow the law, for example reporting illegal content or keeping tax recordsLegal obligation

If you live in India

Under the Digital Personal Data Protection Act, 2023 we use your personal data with your consent, which you give when you create your account, use our features or buy a service, or for other lawful uses the Act allows, such as complying with the law. You have the right to:

  • get a summary of the personal data we hold about you and how we use it;
  • correct, complete, update or erase your personal data;
  • withdraw your consent at any time (for example, by deleting your account or unsubscribing from marketing emails). This doesn’t affect what we did before;
  • have your grievances handled by us (see section 16);
  • nominate another person to use your rights if you die or become unable to do so.

If you are not satisfied with how we handle your grievance, you can complain to the Data Protection Board of India.

If you live in the United States

  • What we collect: identifiers (such as your email address, username, IP address and push token), personal details (name, date of birth, country and phone number), purchase information, internet activity (server logs, sign-in sessions, when you were last active, and records of your calls), and the content you post and send, including photos, videos and voice notes. We never collect the sound of your calls.
  • Location: we do not collect it. The app has no location permission, and a place on a post is a name you typed. We do keep the time zone your phone is set to (section 3), so that emails about your account show your own time.
  • Sensitive information: we use your login details, the contents of your messages and your voice notes only to provide SocialZoom.
  • No selling or sharing: we don’t sell your personal information, and we don’t share it for cross-context behavioural advertising (ads based on what you do on other companies’ apps and websites).
  • Your rights: depending on your state, you can ask to know, access, correct or delete your personal information. Email privacy@socialzoom.co. You can use an authorised agent. We won’t treat you differently for using your rights. If we turn down your request, you can ask us to reconsider by replying to our answer.
  • Do Not Track: we don’t track you across other websites or apps, so we don’t change anything in response to Do Not Track signals.

12. Children

You must be at least 13 years old to use SocialZoom. We check your date of birth when you create your account, and you can’t sign up if you are younger. If we learn that someone under 13 has an account, we delete it. If you are a parent or guardian and think your child under 13 has an account, email privacy@socialzoom.co.

Read about how we fight child sexual abuse and exploitation in our Child Safety Standards.

13. Security

We protect your information with:

  • encryption in transit (HTTPS/TLS) between your device and our servers;
  • voice call sound encrypted between the two phones, so our servers can’t open it (section 6c);
  • access rules checked on our servers for every request. For example, the photos and videos in a private chat can only be opened by the people in that chat;
  • passwords stored only as secure hashes;
  • limits on login attempts;
  • a list of the devices you’re logged in on, and a Log out of other devices button that ends every session except the one on the device you are using.

No system is perfectly secure, and we can’t promise that your information will never be accessed without permission. Use a strong password that you don’t use anywhere else, and tell us straight away at support@socialzoom.co if you think someone has got into your account. If a security breach affects your personal information, we will tell you and the authorities as the law requires.

14. Cookies on our website

Our website sets no cookies. It saves one thing in your browser, in local storage: whether you chose light or dark mode. We use no analytics and no advertising cookies, and the sign-in on the account deletion page is held in the page’s memory only, never saved in your browser. See our Cookie Policy.

15. Changes to this policy

We will update this policy when we add new features or change how we handle information. When we do, we’ll change the "last updated" date. If a change is significant, we’ll tell you in the app or by email before it takes effect.

What changed on 17 September 2026. Notification text is now removed once the notification is delivered, and the records of sent notifications are deleted after 7 days (section 9). We now email you a security alert when someone signs in to your account or your email address or password changes, using the IP address of the sign-in (section 3), and we email you when you get Pro or the verified tick. The IP address is removed once the email is sent, and the record of the email is deleted after 30 days (section 9).

What changed on 15 September 2026. We added voice calls (section 6c), group chats (section 6d) and "Active now" (section 5a). We named Google ML Kit, which the QR code scanner uses on Android (sections 3 and 7). We explained that public photos now reach you through Cloudflare (section 5), that GIFs shown in a chat load from Klipy (section 6b), and that link previews open the linked page (section 6). We corrected where our servers are (France), and when the app asks for notification permission (section 3).

16. Contact us and Grievance Officer

For privacy questions or to use your rights, email privacy@socialzoom.co, or write to Suraj Kumar Rajak (trading as Social Zoom), 38 Bhagwan Nagar, Ashram, New Delhi 110014, India.

Grievance Officer (India). Under India’s Information Technology Rules, 2021 and the Digital Personal Data Protection Act, 2023, you can raise complaints about SocialZoom, including about your personal data, with our Grievance Officer:

  • Name: Suraj Kumar Rajak
  • Email: suraj@socialzoom.co
  • Address: 38 Bhagwan Nagar, Ashram, New Delhi 110014, India

We acknowledge complaints within 24 hours and resolve them within 7 days. Our Terms of Service explain the full complaints process, including faster time limits for some kinds of content and how to appeal.

Questions about this policy? Write to privacy@socialzoom.co and a person will reply.

Other policies

  • Privacy Policy
  • Terms of Service
  • Community Guidelines
  • Child Safety Standards
  • Refund Policy
  • Cookie Policy

The social app for digital marketing.

Coming soon to theApp StoreComing soon onGoogle Play

App

  • Features
  • Safety
  • Questions

Help

  • Help and contact
  • Delete your account
  • Child safety

Legal

  • Privacy Policy
  • Terms of Service
  • Community Guidelines
  • Child Safety Standards
  • Refund Policy
  • Cookie Policy

© 2026 Suraj Kumar Rajak (trading as Social Zoom)